X86 platform drivers
 help / color / mirror / Atom feed
From: Hans de Goede <hansg@kernel.org>
To: "Ilpo Järvinen" <ilpo.jarvinen@linux.intel.com>,
	"Andy Shevchenko" <andy@kernel.org>,
	"Armin Wolf" <W_Armin@gmx.de>
Cc: Hans de Goede <hansg@kernel.org>, platform-driver-x86@vger.kernel.org
Subject: [PATCH] platform/x86: dell-ddv: Fix taking the psy->extensions_sem lock twice
Date: Fri, 20 Jun 2025 19:58:07 +0200	[thread overview]
Message-ID: <20250620175807.418300-1-hansg@kernel.org> (raw)

dell_wmi_ddv_get_property() gets called with psy->extensions_sem
read-locked, it calls dell_wmi_ddv_battery_translate() which calls
power_supply_get_property() on the same psy which again read-locks
psy->extensions_sem.

Lockdep rightfully complains about this:

 ============================================
 WARNING: possible recursive locking detected
...
 kworker/16:3/1230 is trying to acquire lock:
 ffff8c3143417658 (&psy->extensions_sem){++++}-{4:4},
  at: power_supply_get_property.part.0+0x23/0x160
 but task is already holding lock:
 ffff8c3143417658 (&psy->extensions_sem){++++}-{4:4},
  at: power_supply_get_property.part.0+0x23/0x160
...
  Possible unsafe locking scenario:

        CPU0
        ----
   lock(&psy->extensions_sem);
   lock(&psy->extensions_sem);

  *** DEADLOCK ***
...
 Call Trace:
  <TASK>
  ...
  down_read+0x3e/0x180
  ? power_supply_get_property.part.0+0x23/0x160
  power_supply_get_property.part.0+0x23/0x160
  dell_wmi_ddv_battery_translate+0x68/0x1d0 [dell_wmi_ddv]
  ? lock_acquire+0xd9/0x2c0
  dell_wmi_ddv_get_property+0x25/0x240 [dell_wmi_ddv]
  power_supply_get_property.part.0+0x87/0x160
  power_supply_format_property+0xc4/0x3d0
  add_prop_uevent+0x26/0x90
  power_supply_uevent+0xb9/0xf0

This usually works fine, because read-locking can be done multiple times
but if someone tries to write-lock between the 2 read-lock calls then
the second read-lock will block on the write-lock and the write-lock will
be blocked on the first read-lock leading to a deadlock.

The serial is part of the main psy device, not of an extension. Directly
call psy->desc->get_property() in dell_wmi_ddv_battery_translate() to fix
the double-lock issue.

Note this also influences eppid_show() which is called directly rather
then through power_supply_get_property(). This is ok since the ACPI
battery is fully ready to be used when the battery hook's add_battery
callback is called.

Fixes: 058de163a376 ("platform/x86: dell-ddv: Implement the battery matching algorithm")
Signed-off-by: Hans de Goede <hansg@kernel.org>
---
 drivers/platform/x86/dell/dell-wmi-ddv.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/drivers/platform/x86/dell/dell-wmi-ddv.c b/drivers/platform/x86/dell/dell-wmi-ddv.c
index 67f3d7158403..95cc3139f271 100644
--- a/drivers/platform/x86/dell/dell-wmi-ddv.c
+++ b/drivers/platform/x86/dell/dell-wmi-ddv.c
@@ -689,9 +689,11 @@ static int dell_wmi_ddv_battery_translate(struct dell_wmi_ddv_data *data,
 
 	dev_dbg(&data->wdev->dev, "Translation cache miss\n");
 
-	/* Perform a translation between a ACPI battery and a battery index */
-
-	ret = power_supply_get_property(battery, POWER_SUPPLY_PROP_SERIAL_NUMBER, &val);
+	/*
+	 * Perform a translation between a ACPI battery and a battery index. Directly call
+	 * desc->get_property() to avoid locking battery->extensions_sem a second time.
+	 */
+	ret = battery->desc->get_property(battery, POWER_SUPPLY_PROP_SERIAL_NUMBER, &val);
 	if (ret < 0)
 		return ret;
 
-- 
2.49.0


             reply	other threads:[~2025-06-20 17:58 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-06-20 17:58 Hans de Goede [this message]
2025-06-22 18:41 ` [PATCH] platform/x86: dell-ddv: Fix taking the psy->extensions_sem lock twice Armin Wolf
2025-06-22 20:59   ` Hans de Goede
2025-06-22 22:08     ` Armin Wolf
2025-06-23 22:35       ` Sebastian Reichel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250620175807.418300-1-hansg@kernel.org \
    --to=hansg@kernel.org \
    --cc=W_Armin@gmx.de \
    --cc=andy@kernel.org \
    --cc=ilpo.jarvinen@linux.intel.com \
    --cc=platform-driver-x86@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox